--- title: "1.31.4 — Trusted token links and safe short-link previews" description: "Token links now stay on configured frontends, and short-link preview pages escape the destination and preview text they render." date: "2026-10-01" tags: ["release"] canonical: "https://django-mojo.sitesmojo.com/changelog/1-31-4/" --- Token links now stay on configured frontends, and short-link preview pages escape the destination and preview text they render. ### Security - Token links (magic login, password reset, invite) now go only to a configured frontend. A `webapp_base_url` request value, a `?group=` outside the account's own tenant, and an `Origin` header can select a configured frontend but cannot add one. - Short-link preview pages now escape the destination and the preview text. ### Upgrade notes - Set `WEBAPP_BASE_URL`, and `WEBAPP_ALLOWED_ORIGINS` for extra frontends.